@@ -14,3 +14,40 @@ mine_functions:
1414 kubernetes_sa_pub_key_b64:
1515 mine_function: hashutil.base64_encodefile
1616 fname: /etc/kubernetes/pki/sa.pub
17+
18+ x509_signing_policies:
19+ kube_apiserver_client_policy:
20+ - minions: ' *'
21+ - signing_private_key: /etc/kubernetes/pki/ca.key
22+ - signing_cert: /etc/kubernetes/pki/ca.crt
23+ - keyUsage: critical digitalSignature , keyEncipherment
24+ - extendedKeyUsage: clientAuth
25+ - days_valid: 365
26+ kube_apiserver_server_policy:
27+ - minions: ' *'
28+ - signing_private_key: /etc/kubernetes/pki/ca.key
29+ - signing_cert: /etc/kubernetes/pki/ca.crt
30+ - keyUsage: critical digitalSignature , keyEncipherment
31+ - extendedKeyUsage: serverAuth
32+ - days_valid: 365
33+ etcd_client_policy:
34+ - minions: ' *'
35+ - signing_private_key: /etc/kubernetes/pki/etcd/ca.key
36+ - signing_cert: /etc/kubernetes/pki/etcd/ca.crt
37+ - keyUsage: critical digitalSignature , keyEncipherment
38+ - extendedKeyUsage: clientAuth
39+ - days_valid: 365
40+ etcd_server_client_policy:
41+ - minions: ' *'
42+ - signing_private_key: /etc/kubernetes/pki/etcd/ca.key
43+ - signing_cert: /etc/kubernetes/pki/etcd/ca.crt
44+ - keyUsage: critical digitalSignature , keyEncipherment
45+ - extendedKeyUsage: serverAuth , clientAuth
46+ - days_valid: 365
47+ front_proxy_client_policy:
48+ - minions: ' *'
49+ - signing_private_key: /etc/kubernetes/pki/front-proxy-ca.key
50+ - signing_cert: /etc/kubernetes/pki/front-proxy-ca.crt
51+ - keyUsage: critical digitalSignature , keyEncipherment
52+ - extendedKeyUsage: clientAuth
53+ - days_valid: 365
0 commit comments